Built Secure by Design.
Not Secured After the Fact.
KAELUM's closed-loop architecture eliminates the attack vectors that plague open payment networks. Every transaction is Ai-governed, every agent payment is approved by the customer, and every Unit of KLM is issued only against payment.
Structural Advantage
Security Baked into the Architecture
The closed-loop design creates security properties that are hard to retrofit onto open payment networks.
Core Controls
Six Layers of Protection
Security isn't a feature. It's a system - every layer reinforcing the next.
Encryption at Every Layer
TLS 1.3 for all data in transit. AES-256 encryption for data at rest. Field-level encryption for PII and payment data. Keys stored separately from encrypted data.
Zero Raw Card Data
KAELUM never handles raw card data. All payment tokenisation is performed by our PCI DSS Level 1 certified processor layer. Card numbers never touch our systems.
Multi-Factor Authentication
Customers can approve payments and agent authority with passkeys (FIDO2/WebAuthn): Face ID, fingerprint or a security key. Administrative access uses multi-factor authentication, and sensitive actions are logged and time-stamped.
KYC/KYB for Everyone
Merchants, Creators and business partners are verified before they can receive or redeem funds. Customers are verified at defined thresholds. SENTINEL and K.A.T.E. monitor all activity.
Real-Time Sanctions Screening
K.A.T.E. performs automated daily sanctions screening against UK OFSI, EU, and UN consolidated lists. Suspicious activity triggers are reviewed within 24 hours.
Business Continuity
Platform data runs on managed cloud infrastructure with automated backups. Recovery objectives and restore testing are being formalised under our ISO 27001 programme.
K.A.T.E. is your Security Engine
The K.A.T.E. Ai engine, powered by Claude, governs every transaction in real time - not just for commerce, but as your primary fraud and compliance intelligence layer.
- →Real-time fraud detection and anomaly scoring across all transaction patterns
- →Velocity controls flagging unusual frequency, volume, or geographic patterns instantly
- →No Ai output can authorise a payment without deterministic rule validation - Ai-assisted, human-rule governed
- →Prompt injection protections prevent untrusted input from reaching Ai models
- →If Ai is unavailable, deterministic payment rules keep running and K.A.T.E. resumes when service returns
- →K.A.T.E. runs exclusively on Claude by Anthropic, whose commercial terms do not use KAELUM data to train models
- →Dedicated K.A.T.E. Cybersecurity Agent monitors the platform 24/7 with a 5-minute heartbeat
- →ISO 27001 Annex A controls tracked and assessed continuously by the Cybersecurity Agent
K.A.T.E. Cybersecurity Agent
An Ai CISO working around the Clock
Agent 20 in the K.A.T.E. fleet is dedicated entirely to security operations. It works as an Ai Chief Information Security Officer: detecting threats, tracking vulnerabilities, maintaining ISO 27001 controls and managing incidents around the clock, with human approval for sensitive actions such as account suspensions.
Heartbeat
Every 5 mins
Deep Scan
Weekly, Sun 02:00
Governance Tier
Tier 3 to pause
ISO 27001
Live tracking
Threat Detection & Triage
Continuously monitors account security, API abuse, infrastructure anomalies, and data integrity across all platform layers. Critical threats are escalated immediately.
Vulnerability Register
Tracks all identified vulnerabilities with CVSS scoring, SLA deadlines, and remediation plans. Open critical vulnerabilities trigger automatic escalation.
ISO 27001 Compliance Tracking
Every ISO 27001 Annex A control is tracked, assessed, and maintained in a live register. Readiness scores are updated continuously, not just at audit time.
Security Health Score
A composite 0–100 score calculated across account security, API security, infrastructure, data security, and incident response. Updated with each agent cycle.
Incident Response Automation
Security incidents are logged, classified by priority (P1–P4), and tracked through containment, eradication, and recovery. Full audit trail retained.
5-Minute Heartbeat
The Cybersecurity Agent operates on a 5-minute continuous cycle, the highest frequency of any K.A.T.E. agent, with a weekly deep-scan every Sunday at 02:00.
Regulatory Compliance
Built for compliance. Licensing roadmap in motion.
KAELUM is not authorised by the FCA. Our considered view is that the closed-loop design falls within the exclusion at regulation 3 of the UK Electronic Money Regulations 2011 and the corresponding EU exclusion. An independent legal opinion confirming this has not yet been obtained.
UK Electronic Money Regulations (EMR)
Closed-loop exclusion, considered position (legal opinion pending)
EU E-Money Directive
Closed-loop exclusion, considered position (legal opinion pending)
UK GDPR Compliance
Data Protection Policy v1.0 and named Data Protection Lead; DPIAs being completed
AML/CTF and Sanctions
Written policy v1.0, named MLRO, controls in place; legal review pending
PCI DSS Level 1
Via certified processor layer - active
FCA Authorisation Route
Small EMI or licensed partner route under assessment - roadmap
Independent Legal Opinion
Closed-loop exclusion opinion to be commissioned - roadmap
ISO 27001 Certification
Programme underway - roadmap
Data Protection
Your Data, Classified and Protected
Every piece of data KAELUM handles is classified and governed by controls proportional to its sensitivity.
Maximum Protection
KYC documents, bank account details, payment credentials, API secrets, admin credentials.
AES-256 encryption at rest + TLS 1.3 in transit. MFA required for access. Access logged. Strict need-to-know basis.
Strong Protection
Customer PII, transaction records, merchant settlement data, KLM balances, account history.
Encryption at rest and in transit. Access limited to named roles with documented justification. Quarterly access review.
Standard Protection
Operational documentation, internal analytics, system logs, business planning materials.
Access limited to staff members. Not for external distribution without authorisation.
Incident Response
When something happens, we move fast
A documented response procedure so incidents are contained, resolved, and learned from - not hidden.
Detect
The K.A.T.E. Cybersecurity Agent runs continuously with a 5-minute heartbeat, monitoring for threats across account, API, infrastructure, and data security layers. Automated alerts are logged instantly with timestamp, severity, and reference number, no waiting for manual reports.
Continuous, 5-min heartbeatContain
Affected systems isolated. Accounts suspended if financial risk is present. Evidence preserved without forensic alteration. No clean-up before assessment.
Within 15 minutes for P1Notify
Personal data breach: ICO notified within 72 hours as required by UK GDPR. Affected individuals notified without undue delay where high risk exists.
Within 72 hoursEradicate & Recover
Root cause identified and remediated. Services restored from clean state. Enhanced monitoring implemented for 30 days post-incident.
Validated before restorationReview & Improve
Post-incident review within 5 business days. Lessons learned documented. Policy updated if required. Leadership briefing for all critical and high severity incidents.
Within 5 business daysCommerce Currency that's Secure by Default
KAELUM's security isn't an add-on. It's what makes the platform work. Join KAELUM as a Customer, Creator or Merchant.